exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Technical Cyber Security Alert 2009-15A

Technical Cyber Security Alert 2009-15A
Posted Jan 16, 2009
Authored by US-CERT | Site us-cert.gov

Technical Cyber Security Alert TA09-015A - Oracle products and components are affected by multiple vulnerabilities. The impacts of these vulnerabilities include remote execution of arbitrary code, information disclosure, and denial of service.

tags | advisory, remote, denial of service, arbitrary, vulnerability, info disclosure
SHA-256 | ea0007a5a4b7485bd1e8b3bec43af08c2934d79b21d21420850441e3a0d04b6f

Technical Cyber Security Alert 2009-15A

Change Mirror Download

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


National Cyber Alert System

Technical Cyber Security Alert TA09-015A


Oracle Updates for Multiple Vulnerabilities

Original release date: January 15, 2009
Last revised: --
Source: US-CERT


Systems Affected

* Oracle Database 11g, version 11.1.0.6
* Oracle Database 10g Release 2, versions 10.2.0.2, 10.2.0.3, and
10.2.0.4
* Oracle Database 10g, version 10.1.0.5
* Oracle Database 9i Release 2, versions 9.2.0.8 and 9.2.0.8DV
* Oracle Secure Backup, versions 10.1.0.1, 10.1.0.2, 10.1.0.3,
10.2.0.2, and 10.2.0.3
* Oracle TimesTen In-Memory Database, versions 7.0.5.1.0,
7.0.5.2.0, 7.0.5.3.0, and 7.0.5.4.0
* Oracle Application Server 10g Release 3 (10.1.3), version
10.1.3.3.0
* Oracle Application Server 10g Release 2 (10.1.2), versions
10.1.2.2.0 and 10.1.2.3.0
* Oracle Collaboration Suite 10g, version 10.1.2
* Oracle E-Business Suite Release 12, version 12.0.6
* Oracle E-Business Suite Release 11i, version 11.5.10.2
* Oracle Enterprise Manager Grid Control 10g Release 4, version
10.2.0.4
* PeopleSoft Enterprise HRMS, versions 8.9 and 9.0
* JD Edwards Tools, version 8.97
* Oracle WebLogic Server (formerly BEA WebLogic Server) 10.0
released through MP1, 10.3 GA
* Oracle WebLogic Server (formerly BEA WebLogic Server) 9.0 GA,
9.1 GA, 9.2 released through MP3
* Oracle WebLogic Server (formerly BEA WebLogic Server) 8.1
released through SP6
* Oracle WebLogic Server (formerly BEA WebLogic Server) 7.0
released through SP7
* Oracle WebLogic Portal (formerly BEA WebLogic Portal) 10.0
released through MP1, 10.2 GA, 10.3 GA
* Oracle WebLogic Portal (formerly BEA WebLogic Portal) 9.2
released through MP3
* Oracle WebLogic Portal (formerly BEA WebLogic Portal) 8.1
released through SP6

For more information regarding affected product versions, please
see the Oracle Critical Patch Update - January 2009.


Overview

Oracle products and components are affected by multiple
vulnerabilities. The impacts of these vulnerabilities include
remote execution of arbitrary code, information disclosure, and
denial of service.


I. Description

The Oracle Critical Patch Update - January 2009 addresses 41
vulnerabilities in different Oracle products and components. The
document provides information about affected components, access and
authorization required, and the impact from the vulnerabilities on
data confidentiality, integrity, and availability.

Oracle has associated CVE identifiers with the vulnerabilities
addressed in this Critical Patch Update. If significant additional
details about vulnerabilities and remediation techniques become
available, we will update the Vulnerability Notes Database.


II. Impact

The impact of these vulnerabilities varies depending on the
product, component, and configuration of the system. Potential
consequences include the execution of arbitrary code or commands,
information disclosure, and denial of service. Vulnerable
components may be available to unauthenticated, remote attackers.
An attacker who compromises an Oracle database may be able to
access sensitive information.


III. Solution

Apply the appropriate patches or upgrade as specified in the Oracle
Critical Patch Update - January 2009. Note that this document only
lists newly corrected issues. Updates to patches for previously
known issues are not listed.


IV. References

* Oracle Critical Patch Update for January 2009 -
<http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2009.html>

* Critical Patch Updates and Security Alerts -
<http://www.oracle.com/technology/deploy/security/alerts.htm>

* Map of Public Vulnerability to Advisory/Alert -
<http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html>

____________________________________________________________________

The most recent version of this document can be found at:

<http://www.us-cert.gov/cas/techalerts/TA09-015A.html>
____________________________________________________________________

Feedback can be directed to US-CERT Technical Staff. Please send
email to <cert@cert.org> with "TA09-015A Feedback VU#897316" in
the subject.
____________________________________________________________________

For instructions on subscribing to or unsubscribing from this
mailing list, visit <http://www.us-cert.gov/cas/signup.html>.
____________________________________________________________________

Produced 2009 by US-CERT, a government organization.

Terms of use:

<http://www.us-cert.gov/legal.html>
____________________________________________________________________

Revision History

January 15, 2009: Initial release


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBSW+R2HIHljM+H4irAQLnswf/f0DIMhNOZ/sC88dH+pCeSXEDMl7/HZtL
MJEzLABKMeWElPFiA3QY5EVGUEd6CJvdPq9aA2F0f85On+nm6+7SPV2uwc8xl+KM
QEkAOc2jS7fvw7QOXbrUo0kgTg8Z4vyR8km6OpCNOIHopCZ2KDwwSEg31UaOCKW1
JumHsB0unwEKoR3s8/OvWUkKgnWuhz4AtrYFZjzSCxrC+S2sB0gukW+z8RffNRgF
82MijTz62S3I9dcV4ssuBXldBMqeGfY40HxduQjoDBrBdmBuWb5+pEeMd3GblJet
mxgqACcMLIzozfJZczejK4m+K41RZd1nbEK/rpMCsdr9y+a7qFmM9g==
=Wkfo
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    0 Files
  • 7
    May 7th
    0 Files
  • 8
    May 8th
    0 Files
  • 9
    May 9th
    0 Files
  • 10
    May 10th
    0 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close